Recovering symbols from log functions

Recovering symbols from log functions

TL;DR

Stripped binaries still leak their source metadata, and you can recover it:

  • Logging and assert/BUG() macros bake __FILE__, __LINE__ and __func__ straight into .rodata
  • Those string literals hand back original function names and the source directory tree
  • Two Binary Ninja plugins automate it: logrn (renames functions) and arborist (rebuilds the tree)
  • Walkthrough on a tiny example first, then the automation

Read More

Powershell dropper to Amatera stealer

Powershell dropper to Amatera stealer

TL;DR

In-depth analysis of a Powershell dropper:

  • 5 stages malware - from an ASCII-encoded PowerShell dropper down to a custom C2 implant phoning home to a hardcoded IP
  • Obfuscated Powershell scripts with opaq predicats
  • Custom API hashing, aPLib, rolling XOR
  • C2 Beacon with SNI spoofing, json+zip exfiltration, encoded endpoints - Amatera like

More malware write-ups in the same vein: StealC infostealer and GLOBAL GROUP ransomware.

Read More

Static Analysis of GLOBAL GROUP Ransomware: From Encrypted Config to Panic Mode

Static Analysis of GLOBAL GROUP Ransomware: From Encrypted Config to Panic Mode

Analysis Date: January 7, 2026
Methodology: Static analysis only
Sample: f6f7a37b49310287a253dbdf81e22f0593f44111215ca9308e46d2c68516196f


TL;DR

In-depth analysis of GLOBAL GROUP ransomware (RaaS), revealing:

  • An encrypted .config section using a custom XOR + LCG algorithm
  • Hybrid encryption: Curve25519 (ECDH) + SHA-512 (KDF) + HC-128 (stream cipher)
  • The “hash” at config offset 0x843 is actually the builder’s Curve25519 public key
  • Three encryption modes based on file size (including a “panic” mode)
  • Per-file ephemeral keys with proper asymmetric cryptography
  • A builder structure allowing per-victim custom configs

Read More

Reversing a StealC Infostealer

Reversing a StealC Infostealer

TL;DR

Static analysis of a StealC infostealer that uses the Heaven’s Gate technique to transition from 32-bit to 64-bit mode, trying to bypass EDR hooks. Features RC4-encrypted config strings, a custom “MZER” payload marker, and direct syscalls. Successfully extracted the C2 server, decryption key, and 150+ encrypted strings without dynamic execution. Full IOCs at the bottom for anyone who just wants the indicators.

Related static-only deep dives: GLOBAL GROUP ransomware and reversing a random stealer.


Read More

AFL - Introduction

AFL - Introduction

TL;DR

A beginner-friendly walkthrough of coverage-guided fuzzing with AFL:

  • Install and build AFL (American Fuzzy Lop) from source
  • Instrument and compile a small open-source C program for fuzzing
  • Run AFL, read its status screen and collect the first crashes

Read More

Delitcrypt

Delitcrypt

TL;DR

Reversing a Rust string-obfuscation macro and automating the decryption:

  • Reversing litcrypt, a Rust proc-macro that XOR-obfuscates strings at compile time
  • Locating the encrypted strings and the runtime decryption routine in the compiled binary
  • Building a Binary Ninja plugin (and learning the API) to recover the plaintext automatically
  • A methodology-first write-up: the real reversing process, dead-ends included

Read More